HNHacker News
TopNewBestAskShowJobs

lirantal

131 karma · joined October 24, 2014

submissionscomments
lirantal··on Show HN: Text adventure to learn skills and agents
lovely design, I enjoyed playing it
lirantal··on Qodo CLI agent scores 71.2% on SWE-bench Verified
Slick. This applies to the new Qodo Command CLI, yes?

I updated to the latest version last night. Enjoyed seeing the process permission toggle (rwx). Was a refreshing change to keep the security minded folks less in panic with all the agentic coding adoptions :-)

lirantal··on [dead]
A write-up on flawed MCP servers that are written without security best practices. Hope this helps raise awareness!
lirantal··on Datadog CEO on AI and Observability
reminds me of the days from about a decade ago when Big Data was a thing and there were so many anomaly detection products. Anyways, agree with the overall sentiment here and Datadog only stands to gain from a broadened market of LLM traffic / usage observability play.
lirantal··on Tessl raises $125M for a zero maintenance, spec-centric AI software dev platform
Congrats team!
lirantal··on How to Process Scheduled Queue Jobs in Node.js with BullMQ and Redis on Heroku
Process long-running tasks in Node.js with background jobs. Learn how to use BullMQ and Redis on Heroku to create a scalable and reliable background job processing system.
lirantal··on [dead]
Hi Ruby Devs

I've once shared an article with y'all here about setting up a local Ruby development environment, but folks were asking - what about setting up Ruby inside a container?

Well then, Mikhail Tereschenko heard you :-)

Check out his article on how to setup an entire Ruby on Rails development (and production!) local development environment with Ruby Docker containers and Docker Compose

The environment sets up:

An nginx HTTP server

A Ruby application server

A PostgreSQL database server

All complete with source code and GitHub repository for code references

lirantal··on Show HN: Amplication v1.0 – open-source generator for Node.js microservices
Congrats on the new Amplication v1.0 launch! I was really excited for the plugins and were looking forward to learn how to build my own to extend the platform. That JWT Auth looks like a great project starter too :-)
lirantal··on [dead]
Last week I updated my article on this topic :-) I've specifically extended on why the the base image recommendation should not be alpine but rather a supported slim version of Debian. You probably want to dive into that first best practice in the article but if this is the first time you're reading it and you are often tasked with building container images and Dockerfile then you definitely want to give this comprehensive article a visit.
lirantal··on Node-ipc added dependency on maintainer's peacenotwar module
Correct, specifically it were versions 10.1.1 and 10.1.2 that did so and as of now are removed.
lirantal··on Node-ipc added dependency on maintainer's peacenotwar module
More detailed write-up on what exactly happened with node-ipc and the events that lead to it from a week ago (March 8th) here: https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-pack...
lirantal··on Node-ipc spreading malware with NPM packages
Stay safe everyone
lirantal··on Popular NPM module node-ipc added malware targeting Russian developers
More detailed write-up and summary of events that I put up here: https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-pack...
lirantal··on Protestware: “peacenotwar” NPM package drops anti-war message on user's desktop
The full timeline of events and details about how this unfolds are covered here in my write-up: https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-pack...
lirantal··on Ask HN: Any weird tips for weight loss?
Drink a lot of water. Every time you feel hungry, drink a bottle of water.
lirantal··on Show HN: Never have an SSL certificate expire again
Honestly, I'm just amazed at how this didn't exist yet... Awesome job Anton building this!
lirantal··on Log4Shell Remediation Cheat Sheet
Great and useful content. Most importantly, has been shown to be updated every time with new learnings, as the log4j issue is a moving target. Good stuff by the team!

Disclaimer, I work at Snyk.

lirantal··on Ask HN: Tools you have made for yourself?
I built dockly - https://github.com/lirantal/dockly

An immersive terminal interface for managing docker containers to help me do that from the command line

lirantal··on Cheatsheet: Top Application Security Acronyms
Nice job with that alyssam!
lirantal··on Show HN: Vuln Cost – immersive VS Code extension to surface vulnerabilities
ooh thanks! would be really happy to capture any extra feedback if you have ideas for what to improve
lirantal··on Show HN: Vuln Cost – immersive VS Code extension to surface vulnerabilities
@danpalmer appreciate that. If and when you try it out and have any feedback I'd be happy to capture that and see how it works with our plans for it.
lirantal··on Sequelize ORM NPM library found vulnerable to SQL Injection attacks
kudos to Kirill from the security research team who worked on this discovery as well as providing the fixes (!) and many thanks and appreciation to the Sequelize project maintainers who worked with us on the responsible disclosure and promptly issued fixes to vulnerable versions where necessary.

Sequelize is a pretty popular ORM for Node.js projects so you should probably test your project with snyk and ensure you aren't vulnerable (npm audit is still lagging behind on this vulnerability for 24 days currently).

lirantal··on Picking a JavaScript Library
happy to see that security is part of the evaluation :-)
lirantal··on Ctop – commandline monitoring for containers
Really cool. I also wrote a similar tool - Dockly, which provides a more complete management of docker containers through the CLI.

https://github.com/lirantal/dockly